Live data from Hacker News

Google knows nearly every Wi-Fi password in the world

blogs.computerworld.com

141–150 of 312 posts

Re: Google knows nearly every Wi-Fi password in the world

#141
post #97
post #72

Earlier quoted context omitted.

Acknowledged. I still argue that Google's getting more than its fair share of abuse, though.

Fair share? Abuse? It is a criticism made against a corporation. It deserves scrutiny and a critical eye whenever it fails, regardless of what it's competitors do. I hate to say it because I abhor the word, but this reeks of fanboyism.

[deleted]

Re: Google knows nearly every Wi-Fi password in the world

#142
post #52

The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…

Honestly, I use WEP encryption because I know that WiFi security is a house of cards in general. As you've said, it's enough to prevent the typical user from leeching bandwidth. The nice thing about using WEP is that if someone does end up using my network for something nefarious and I end up holding the bag for it, I (or an expert witness) can point out that WEP is known to be vulnerable in court giving me an out.

- Until they link this post back to you, and argue that you knowingly weakened your security.

- Until they argue that the default encryption level on routers now is WPA/WPA2, so by enabling WEP you were actively lowering the security level.

- Until they argue that your technical background means that you should have known better that WEP is crackable.

Re: Google knows nearly every Wi-Fi password in the world

#143
post #110

Earlier quoted context omitted.

> passwords are either easy for computers to crack or hard for humans to remember Obligatory xkcd comic: https://xkcd.com/936/

I loathe whenever people post that comic for one simple reason. Although mathematically the password given in the comic has a higher entropy and would take more time to crack under normal circumstances, the problem is that it follows a very simple and easily describable pattern: smash (four) dictionary words together into a combination. Crackers will simply start using wordlist rules to generate large lists of meshed…

I also add digits, some punctuation, a misspelling or two and the words are not in English. Oh, and I've got different passwords everywhere.

Re: Google knows nearly every Wi-Fi password in the world

#144
post #9

Google also knows all the secrets of General David Petraeus, or anyone else that uses Gmail. And everything you've (secretly) searched for. Google's business model is based on aggregating that information and gaining value out of the data, mostly in the form of advertising. As soon as it lets a major secret out, even just once, it's game over, and no-one will ever trust a secret to Google again. This is why they publ…

I agree that it's unlikely Google as a whole would decide to read/use confidential data. on the other hand, the idea that someone w/in Google might abuse their position is completely plausible. if we know that people at the NSA were passing around phone sex calls by US troops, do you really want to keep trusting that no-one at Google will ever do anything problematic w/ yr data? edit: to be clear, I use Google servic…

All it takes a few, not "Google as a whole."

I am not a fan of Google, but I feel that in Larry Page's era few things are sacred when it comes to making money. Maybe a Googler decides to read some Goldman Sachs' trader emails, or Google in general can sell trend data. Who knows?

They have (IMO) ruined search and destroying any trust in its fairness, yet they are a monopoly, have a lot of goodwill and nothing is happening. So far.

Re: Google knows nearly every Wi-Fi password in the world

#145
post #52

The author is worried about WiFi passwords? If you trust that your WiFi is secure in general, you're in trouble. WPS is horribly insecure, for example, and that's what most home users use. Most user-chosen passwords are incredibly easy to guess for another. The better thing to do is to assume that your network traffic is always under surveillance (since the NSA is tapping Tier1 network providers), and to encrypt ever…

Honestly, I use WEP encryption because I know that WiFi security is a house of cards in general. As you've said, it's enough to prevent the typical user from leeching bandwidth. The nice thing about using WEP is that if someone does end up using my network for something nefarious and I end up holding the bag for it, I (or an expert witness) can point out that WEP is known to be vulnerable in court giving me an out.

That does not make much sense. You're being paranoid and actively helpless.

WPA2 is in fact quite secure if you're careful about your passkey and who you give it to.

Re: Google knows nearly every Wi-Fi password in the world

#146
post #55

Or, in other words, Google remembers the things that we agree to have it remember.

In contract law, there's a concept called "meeting of the minds". A contract is formed when there has been a meeting of the minds between two parties as to what the deal is, and the parties have taken some concrete action to initiate the deal - often signing something, or shaking hands, or handing over money, or something like that. The operative question is: when someone signs into a Google account on an Android dev…

I believe that there is also the concept of "Let the Buyer Beware". If someone says, which is what the android service does, that it is going to backup your data to the cloud. Not much of a stretch to think of your wifi password as part of that.

Re: Google knows nearly every Wi-Fi password in the world

#147

Earlier quoted context omitted.

Is this Googles failure or are goverments the issue? You cannot prevent that some entity will have private data about you, once you start using mainstream online services whose focus is on mainstream issues like ease of use, portability of data and seamless access from multiple devices. Ensuring that the legal frameworks we live within have strong privacy laws makes more sense to me, because what are the realistic op…

Is this Googles failure or are goverments the issue? Both, but any Google executive aware of the abuses could have anonymously tipped off Wikileaks or some other journalist. None did. To explain Google's behavior, classic diffusion of responsibility is all that is necessary. Without any such dissent, it's no surprise that the government abused its power. Snowden is a significant outlier... hiring policies are intende…

"Both, but any Google executive aware of the abuses could have anonymously tipped off Wikileaks or some other journalist. None did."

We do not know this and it would be questionable if the risk associated with such an act would be worth it considering that Google can actually use its resources to move things in a legal way. (via courts, lobbying in Washington etc.)

"To explain Google's behavior, classic diffusion of responsibility is all that is necessary. Without any such dissent, it's no surprise that the government abused its power."

I remember Google protesting (SOPA) and actively pursuing privacy initiatives multiple times in the last years and even pull out of the Chinese market.

They release detailled copyright removal reports: http://www.google.com/transparencyreport/removals/copyright/

They let you take all your data out of all Google products: http://www.dataliberation.org/takeout-products

They fight governments data requests in courts (sometimes successfully) and release strongly worded statements when they are allowed to.

Suggesting that we ended up with an abusive goverment because Google slavishly followed orders seems unrealistic to me.

"Snowden is a significant outlier... hiring policies are intended to prevent the hire of the kind of person who would do what he did. The scary thing is that Google's hiring practices achieve the same thing."

Google as a company would arguably not exist anymore, if its developers/admins constantly leaked data.

The survival of the NSA does not depend on public trust and a positive public image - Google does.

Re: Google knows nearly every Wi-Fi password in the world

#148
post #34

Earlier quoted context omitted.

Given that Google has a VC arm, I am stunned every time I run into a VC who uses gmail and other google-hosted services as part of their business. They are handing their competition an enormous chunk of their business proprietary information and trusting them not to peek at it without even a contract. To me, that level of naivety with respect to operational security is just baffling. All it takes is one unscrupulous…

For this to be a worry, every person up both branches of a very large hierarchical organization tree--all the way up to where a Google Ventures employee and a Gmail developer both report to the same person--would have to agree to it. Google Ventures, no matter how spectacularly they might do as VCs, will always be several orders of magnitude less important to Google than Gmail. Google Ventures invests $300 million pe…

"deliver 3x on the money invested a few years before. They are still delivering less than $1 billion, less than 2% of Google's revenue."

That's virtually all profit, not revenue, and WSt would be thrilled. And all you would need a crooked employee to do that. Maybe a GV partner could approach a SRE...ala http://www.sec.gov/news/press/2011/2011-53.htm

Goldman Sachs and PG board member has been corrupted that way, imagine a lowly engineer that could triple his salary in a heartbeat.

Re: Google knows nearly every Wi-Fi password in the world

#149
post #134

Your WiFi password is only useful for someone who is within 100 feet of your house. If you have federal agents surveilling you from 100 feet away you have way bigger problems than your WiFi password.

In general, I agree that distance is a factor. However, the range at which signals can be intercepted is substantially greater and repeating and recording equipment also comes into play.

As do actors other than Federal agents.

Re: Google knows nearly every Wi-Fi password in the world

#150
post #28
post #10

For convenience, most people won't opt out of it. Most people won't bother at all. Google employees(or even NSA if you don't do anything illegal) coming to your home/office to use your WiFi is a joke! Only the paranoid ones are perturbed by these kinds of revelations, and they are ready to face the inconvenience caused. I didn't use last pass until recently when keeping a difficult password on every site became a maj…

The encryption/decryption is done client side. This is a simple version of how it works, your master password isn't sent to lastpass, just an encryption key which is created with your email address and master password. On the website this is done client side with javascript. When you click on the pencil icon, you are reading the decrypted file, which you have decrypted on your own computer, with javascript.

Client-side decoding in a web app is not secure against the host of the web app, because the decryption code can be changed at any time to contain arbitrary backdoors. Lastpass stores the encrypted secret, and they serve the Javascript that decrypts the secret, so they should be assumed to have access to the secret.
Post reply on HN